Source-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[src/netbsd-3-0]: src/doc Ticket 1368.



details:   https://anonhg.NetBSD.org/src/rev/e5bef58b7c5d
branches:  netbsd-3-0
changeset: 579240:e5bef58b7c5d
user:      tron <tron%NetBSD.org@localhost>
date:      Thu Jun 08 22:23:09 2006 +0000

description:
Ticket 1368.

diffstat:

 doc/CHANGES-3.0.1 |  9 ++++++++-
 1 files changed, 8 insertions(+), 1 deletions(-)

diffs (20 lines):

diff -r 0bed9d7fd8fb -r e5bef58b7c5d doc/CHANGES-3.0.1
--- a/doc/CHANGES-3.0.1 Thu Jun 08 22:20:42 2006 +0000
+++ b/doc/CHANGES-3.0.1 Thu Jun 08 22:23:09 2006 +0000
@@ -1,4 +1,4 @@
-#      $NetBSD: CHANGES-3.0.1,v 1.1.2.53 2006/06/04 22:20:05 ghen Exp $
+#      $NetBSD: CHANGES-3.0.1,v 1.1.2.54 2006/06/08 22:23:09 tron Exp $
 
 A complete list of changes from the NetBSD 3.0 release to the NetBSD 3.0.1
 release:
@@ -494,3 +494,10 @@
        freetype2.  
        [tron, ticket #1354]
 
+games/tetris/scores.c                          1.14
+
+       Check data read from "tetris.scores". This address CVE-2006-1539.
+       A standard NetBSD installation is not as much risk because "tetris"
+       is set-group-ID "games", and users shouldn't be in that group.
+       [dan, ticket #1368]
+



Home | Main Index | Thread Index | Old Index